Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1354359
| Path | csiph.com!aioe.org!gothmog.csi.it!bofh.it!news.nic.it!robomod |
|---|---|
| From | "Austin S. Hemmelgarn" <ahferroin7@gmail.com> |
| Newsgroups | linux.kernel |
| Subject | Re: Thoughts on tightening up user namespace creation |
| Date | Wed, 09 Mar 2016 20:10:01 +0100 |
| Message-ID | <raREB-3Sz-7@gated-at.bofh.it> (permalink) |
| References | <raidP-4Nk-3@gated-at.bofh.it> <raQSe-3kQ-17@gated-at.bofh.it> <raRuW-3zK-7@gated-at.bofh.it> |
| X-Original-To | Colin Walters <walters@verbum.org>, Kees Cook <keescook@chromium.org>, Andy Lutomirski <luto@amacapital.net> |
| Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=subject:to:references:cc:from:message-id:date:user-agent :mime-version:in-reply-to:content-transfer-encoding; bh=ffKuyAUV1TxYNbTlFmtnnsMdycXwm9+Ju9w5hv+HqTY=; b=SZWRfqtEB8vnl9scjTQN3Ty6nt98c2PuSJ5HrWSmh6etb1SOjSaswANlpVFWTJBvbK 2nD2SAnRxAJRHPQMtGMEbbi57wGsu1NVQYBtNizT3e2eiUfX60Itw3VSK6+y2qEjwUXK oLUTB0z915W14J3NQ/UflK/v71k7Vx85WeTNdlb/g5GuFwF4eDaYdEx/VTktdorkoEs/ txeX7RRxQGnlqExxJYH+5QdMEy7kxYtlNHmqOPMhOP77LUoYMTwYlkKUwrk0OdsRNrfn HWT0M8Zhf9T4/blUlOqLkA51cPjxneoZaMwPHDa6FMrPpcI4+18q+NgjOtlqafpMWXwh reAQ== |
| X-Google-Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:subject:to:references:cc:from:message-id:date :user-agent:mime-version:in-reply-to:content-transfer-encoding; bh=ffKuyAUV1TxYNbTlFmtnnsMdycXwm9+Ju9w5hv+HqTY=; b=Iy4RrkHDKUPek/j5xjyAbYh599/pz8xtIvwK+g2BBTnxXGb75bEpGHc6ur8UuY590f XCmI/9l/UJ/Yy/eE6qVZ9X07jcdmiS4OkQFtRaKhHDp3u33WqMV86uK43M66FDG6vL74 J7vg+NjO8rAL17hU53D25Vq1HN9Z/D3ad4OuMOCQSXA5nvTc1hrVePIjUVMczpeW5Nhw B6DiMVrVUa2toHYlqh0/vezVl8KRMbMz7AfLqNyaL9w5IUkgYt7C5llO8CNl/XixYOrt qNPo3lTk3oiUUjo7l1lL809+fQlUABvUlAt179LuLDUw7MXXH5EUcq87spHg0nMyF1k8 QP+w== |
| X-Gm-Message-State | AD7BkJISB+5wemtray9c2NSlmjmFf9hK9zJN/b50x5/MJUL8KjxGikzONwGhbQPP1A9Xxg== |
| X-Received | by 10.55.71.146 with SMTP id u140mr44338870qka.14.1457550324781; Wed, 09 Mar 2016 11:05:24 -0800 (PST) |
| User-Agent | Mozilla/5.0 (Windows NT 6.1; WOW64; rv:38.0) Gecko/20100101 Thunderbird/38.6.0 |
| MIME-Version | 1.0 |
| Content-Type | text/plain; charset=windows-1252; format=flowed |
| Content-Transfer-Encoding | 7bit |
| X-Antivirus | avast! (VPS 160309-0, 2016-03-09), Outbound message |
| X-Antivirus-Status | Clean |
| Sender | robomod@news.nic.it |
| List-ID | <linux-kernel.vger.kernel.org> |
| X-Mailing-List | linux-kernel@vger.kernel.org |
| Approved | robomod@news.nic.it |
| Lines | 48 |
| Organization | linux.* mail to news gateway |
| X-Original-Cc | linux-kernel@vger.kernel.org, "Eric W. Biederman" <ebiederm@xmission.com>, Linux Containers <containers@lists.linux-foundation.org>, Alexander Larsson <alexl@redhat.com>, Serge Hallyn <serge.hallyn@ubuntu.com>, Stephane Graber <stgraber@ubuntu.com>, Seth Forshee <seth.forshee@canonical.com> |
| X-Original-Date | Wed, 9 Mar 2016 14:04:26 -0500 |
| X-Original-Message-ID | <56E073BA.3000009@gmail.com> |
| X-Original-References | <CALCETrU4+zTKABz1foEA=an3XYbe_UXxn_w9=1GjVzMe5DXXPw@mail.gmail.com> <CAGXu5jLB5==RAs9YrsPi4m6ZBPn3UtbCzagu_+gr-rtSgKzB1Q@mail.gmail.com> <1457549467.650797.544465346.49653120@webmail.messagingengine.com> |
| X-Original-Sender | linux-kernel-owner@vger.kernel.org |
| Xref | csiph.com linux.kernel:1354359 |
Show key headers only | View raw
On 2016-03-09 13:51, Colin Walters wrote: > On Wed, Mar 9, 2016, at 01:14 PM, Kees Cook wrote: >> On Mon, Mar 7, 2016 at 9:15 PM, Andy Lutomirski <luto@amacapital.net> wrote: >>> Hi all- >>> >>> There are several users and distros that are nervous about user >>> namespaces from an attack surface point of view. >>> >>> - RHEL and Arch have userns disabled. >>> >>> - Ubuntu requires CAP_SYS_ADMIN >>> >>> - Kees periodically proposes to upstream some sysctl to control >>> userns creation. >> >> And here's another ring0 escalation flaw, made available to >> unprivileged users because of userns: >> >> https://code.google.com/p/google-security-research/issues/detail?id=758 > > Looks like Andy won't have to eat his hat ;) > >> The change in attack surface is _substantial_. We must have a way to >> globally disable userns. > > No one would object if it was enabled but only accessible to > CAP_SYS_ADMIN though, right? This could be useful for > writing setuid binaries that expose some of the features, but e.g. not > CAP_NET_ADMIN. At least Google Chrome (and probably Chromium) is using user namespaces without CAP_SYS_ADMIM (although AFAIUI, it's because they can't use the other namespace types effectively as a regular user). > > Andy's suggestion of having this be a per-namespace setting makes > sense to me. Currently some container tools that do use userns > are by default denying it to be recursive (Sandstorm.io and Docker 1.10 at least) > by using a seccomp filter on clone(). If we had this setting that > filter wouldn't be necessary, and would solve the issue that seccomp filters > aren't robust against the kernel adding new API, e.g. a new CLONE_NEWUSER_NONEWPRIVS > which might enable chroot() but not CAP_NET_ADMIN. > Personally, I like the suggestion from Alexander Larsson to make a cgroup controller. Container tools obviously want some degree of hierarchical control (even if it's just saying that the hierarchy ends here), and it would simplify the possibility of running more than one container stack on the same host (I know at least a couple people who would love to be able to safely use Docker on the same host as LXC or lmctfy).
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Thoughts on tightening up user namespace creation Andy Lutomirski <luto@amacapital.net> - 2016-03-08 06:20 +0100
Re: Thoughts on tightening up user namespace creation "Serge E. Hallyn" <serge.hallyn@ubuntu.com> - 2016-03-08 07:10 +0100
Re: Thoughts on tightening up user namespace creation Andy Lutomirski <luto@amacapital.net> - 2016-03-08 19:40 +0100
Re: Thoughts on tightening up user namespace creation "Serge E. Hallyn" <serge@hallyn.com> - 2016-03-08 23:50 +0100
Re: Thoughts on tightening up user namespace creation Alexander Larsson <alexl@redhat.com> - 2016-03-08 11:10 +0100
Re: Thoughts on tightening up user namespace creation ebiederm@xmission.com (Eric W. Biederman) - 2016-03-08 17:50 +0100
Re: Thoughts on tightening up user namespace creation Kees Cook <keescook@chromium.org> - 2016-03-09 19:20 +0100
Re: Thoughts on tightening up user namespace creation Colin Walters <walters@verbum.org> - 2016-03-09 20:00 +0100
Re: Thoughts on tightening up user namespace creation "Austin S. Hemmelgarn" <ahferroin7@gmail.com> - 2016-03-09 20:10 +0100
Re: Thoughts on tightening up user namespace creation "Serge E. Hallyn" <serge@hallyn.com> - 2016-03-09 20:30 +0100
Re: Thoughts on tightening up user namespace creation Kees Cook <keescook@chromium.org> - 2016-03-09 20:30 +0100
Re: Thoughts on tightening up user namespace creation "Serge E. Hallyn" <serge@hallyn.com> - 2016-03-09 20:10 +0100
Re: Thoughts on tightening up user namespace creation Kees Cook <keescook@chromium.org> - 2016-03-09 20:20 +0100
csiph-web